Solved

Access to server thru RWW

Posted on 2010-11-12
11
529 Views
Last Modified: 2012-05-10
Hello Experts

I need to give a standard user in a SBS 2008 network access to the server.  I don't want to make the account a Network Admin because it is an outside user from the company.  The user can access the RWW, but the option to connect to server isn't there.

Is there a way to give this user server access thru RWW without making them a network admin?

Thanks.
0
Comment
Question by:Ray Drummond
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 23

Assisted Solution

by:ormerodrutter
ormerodrutter earned 75 total points
ID: 34121666
No. Only admin allows to RDP to SBS server, without using third party software/tool.

One thing you can do (although I am against the idea of allowing an ordinary user to mess with my SBS server, let alone an outsider!!) is to install something like VNC server on your SBS and VNC viewer on his computer, configure a password if you wish and he can connect this way.

VNC is more like an user support tool that he would take control of the mouse+keyboard and you can actually see what he is doing on the server monitor.
0
 
LVL 77

Accepted Solution

by:
Rob Williams earned 175 total points
ID: 34133565
What exactly do you want them to be able to do?

There are the remote server administrator tools. This allows them to administer the server without having direct access, however I suspect this is more control that you want to give:
XP:
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e487f885-f0c7-436a-a392-25793a25bad7&displaylang=en#SystemRequirements
Vista:
http://www.microsoft.com/downloads/en/details.aspx?FamilyId=9FF6E897-23CE-4A36-B7FC-D52065DE9960&displaylang=en
Win7:
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d&displaylang=en

If you want to give them access to Active Directory but control what they want to do you can use delegation:
http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html
0
 

Author Comment

by:Ray Drummond
ID: 34137345
They just need to be able to access a billing system on the server.  I don't want them doing anything else.
0
Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

 
LVL 23

Expert Comment

by:ormerodrutter
ID: 34137389
No I don't think you can achieve your objective without giving him the Admin access. Shouldn't really installed the billing system on the server unless it is a client/server application.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 34137447
Agreed.
Why are you running the application on the server?
SBS is not intended as an application server. Remote access is for administration only and the server is optimized for background services not applications.
0
 

Author Comment

by:Ray Drummond
ID: 34137470
It wasn't me.  This is a client that was picked up that already had a SBS in place.  The prior company installed it all and I'm just trying to make it work.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 34137905
The problem is the only way to run remote desktop is as an admin on SBS. Though you can limit some permissions this user needs to have admin to logon and full rights to run the application, access the program folder, the data file, and possibly the registry. Very difficult to restrict a user in this situation. You could create a new admin account and using deny permissions restrict access to much of the data, but they would still have the right to administer the server.
0
 

Author Comment

by:Ray Drummond
ID: 34139781
Ok, so I guess I'll see what I can do about moving this billing solution to another computer.  They only have the one SBS on their network.  I really don't want here having any kind of access beyond what she absolutely needs.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 34141447
I can appreciate your predicament but perhaps a PC would be a better option.
0
 

Expert Comment

by:Cr0n0s
ID: 34392432
Hello,

A workaround for this issue is to place the server in the computer group, give the user the required access , afterwards place the computer back in server group in AD.

The setting is stored.

grtz
Smartsys
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 34392509
Ignoring the fact that moving OU's will not resolve the issue, if you place the SBS in the computer OU, group policy for computers will be applied and could cause all sorts of chaos on a DC.
0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question